CVE-2026-59310
VMware · Cloud Foundation, vCenter, vSphere Foundation, Telco Cloud Infrastructure, Telco Cloud Platform
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
Executive summary
A critical directory traversal vulnerability in the VMware vCenter Syslog server allows unauthenticated remote attackers to achieve arbitrary code execution.
Vulnerability
This is a directory traversal vulnerability (CWE-22) located in the Syslog server component. An unauthenticated attacker can leverage this flaw to access restricted directories and execute arbitrary code, compromising the underlying host.
Business impact
The ability for an unauthenticated attacker to execute code remotely carries a CVSS score of 9.8, indicating a critical risk of total system takeover. This could result in complete loss of control over the virtual infrastructure, data theft, or the installation of persistent malicious backdoors.
Remediation
Immediate Action: Upgrade all affected VMware components to the latest versions as specified in the official Broadcom security advisory.
Proactive Monitoring: Inspect Syslog server logs for path traversal patterns, such as sequences including dot-dot-slash, and monitor for unexpected process execution on the vCenter appliance.
Compensating Controls: Deploy a Web Application Firewall or network intrusion detection system to filter malicious payloads targeting the Syslog server interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the potential for remote code execution, organizations must treat this vulnerability with the highest priority. Patching is the only effective way to remove the underlying defect and prevent potential exploitation.